Malicious NPM package was targeted the software developers by abusing the legitimate third-party tool known as ChromePass , a tool to recover the password from the Chrome browser. Researchers from Reversinglab found that this package has 12 published versions, in total over 1,283 downloads since the package was initally published at the end of February 2019. The author of this package goes by the name chrunlee who has actively developed nearly 61 repositories in GitHub, also the GitHub repository has been linked to the website hxxps://chrunlee(.)cn.”]
Source: https://gbhackers.com/malicious-npm-package-steals-chrome-browser-passwords/

